Realistic SOC case investigation over a multi-source log corpus
An EDR alert fires on a finance workstation. Work a realistic multi-source corpus to reconstruct a phishing-to-exfil intrusion end to end.
A DLP alert on after-hours cloud uploads. Separate a departing employee's data theft from the noise of a busy finance team.
Kerberoasting leads to a forged ticket. Trace an identity attack across DC, Sysmon and authentication logs to the domain-dominance step.
A trusted software update turns malicious. Hunt DLL sideloading and signed-binary abuse spreading from a software-deployment server.
VPN compromise to pre-encryption staging. Catch the intrusion in the window before detonation: recon, defence evasion, backup tampering and shadow-copy deletion.